Phone hacking

Phone hacking


Phone hacking is the practice of intercepting telephone calls or voicemail messages, often by accessing the voicemail messages of a mobile phone without the consent of the phone's owner. The term came to prominence during the News International phone hacking scandal, in which it was alleged (and in some cases proved in court) that the British tabloid newspaper the News of the World had been involved in the interception of voicemail messages of the British Royal Family, other public figures, and the murdered schoolgirl Milly Dowler

Risks

Although any mobile phone user may be targeted, "for those who are famous, rich or powerful or whose prize is important enough (for whatever reason) to devote time and resources to make a concerted attack, there are real risks to face.

Techniques
Voicemail
Phone hacking often involves unauthorized access to the voicemail of a mobile phone.

Contrary to what to their name suggests, scandals such as the News International phone hacking scandal have little to do with hacking phones, but rather involve unauthorised remote access to voicemail systems. This is largely possible through weaknesses in the implementations of these systems by telcos.

Voicemail
Phone hacking often involves unauthorized access to the voicemail of a mobile phone.

Contrary to what to their name suggests, scandals such as the News International phone hacking scandal have little to do with hacking phones, but rather involve unauthorised remote access to voicemail systems. This is largely possible through weaknesses in the implementations of these systems by telcos.

Since the early days of mobile phone technology, service providers have allowed access to the associated voicemail messages via a landline telephone, requiring the entry of a Personal Identification Number (PIN) to listen to the messages. Many mobile phone companies used a system that set a well-known four digit default PIN that was rarely changed by the phone's owner, making it easy for an adversary who knew both the phone number and the service provider to access the voicemail messages associated with that service. Even where the default PIN was not known, social engineering could be used to reset the voicemail PIN code to the default, by impersonating the owner of the phone during a call to a call centre.[5][6] Many people also use weak PINs that are easily guessable; to prevent subscribers from choosing PINs with weak password strength, some mobile phone companies now disallow the use of consecutive or repeat digits in voicemail PIN codes.

During the mid-2000s, it was discovered that calls enimating from the handset registered against a voicemail account were put straight through to voicemail without the caller being challenged to enter a PIN. An attacker could therefore use caller ID spoofing to impersonate a victim's handset phone number and thereby gain unauthorized access to the associated voicemail without a PIN.

Following controversies over phone hacking and criticizm that was levelled at mobile service providers who allowed access to voicemail without a PIN, many mobile phone companies have strengthened the default security of their systems so that remote access to voicemail messages and other phone settings can no longer be achieved via a default PIN. For example, AT&T announced in August 2011 that all new wireless subscribers would be required to enter a PIN when checking their voicemail, even when checking it from their own phones, while T-Mobile stated that it "recommends that you turn on your voice mail password for added security, but as always, the choice is yours."

Handsets

An analysis of PIN codes suggested that ten numbers represent 15% of all iPhone passcodes, with "1234" and "0000" being the most common, with years of birth and graduation also being common choices.[11] Four-digit PINs are significantly easier to brute force than passwords, allowing someone with physical access to a handset to feasibly determine the PIN in a short time. Enterprises may therefore implement policies enforcing strong passwords through mobile phone management systems.

Mobile phone microphones can be activated remotely, without any need for physical access.[14][15][16][17][18][19] This "roving bug" feature has been used by law enforcement agencies and intelligence services to listen in on nearby conversations.

Other techniques for phone hacking include tricking a mobile phone user into downloading malware which monitors activity on the phone, or bluesnarfing, which is unauthorized access to a phone via Bluetooth.